Описание
The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server due to a path traversal in the HLS endpoint.
Ссылки
- Release Notes
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.1.1 (исключая)
cpe:2.3:a:framasoft:peertube:*:*:*:*:*:*:*:*
EPSS
Процентиль: 6%
0.00024
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 3.7
debian
10 месяцев назад
The vulnerability allows any authenticated user to leak the contents o ...
CVSS3: 3.7
github
10 месяцев назад
The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server due to a path traversal in the HLS endpoint.
EPSS
Процентиль: 6%
0.00024
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-22